Drive-By Downloads
What Is A Drive-By Download?
Usually, to download a file, you need to click on something or enable the download in some way. But in a drive-by download, malicious software can be downloaded onto your computer without you clicking anything. Drive-by downloads exploit security flaws in your computer to secretly install malicious files without you even knowing.
Compromised Websites
A drive-by download can occur if you use old or out-of-date software and visit a malicious website. The code on the webpage will check your browser for vulnerabilities. If a flaw is found, the malicious software will exploit this and install itself on your computer. A malicious webpage typically contains many different types of code in hopes that one of them can exploit a security vulnerability on your computer.
Attack Methods
Cybercriminals often use phishing attacks like emails or text messages to lure you into visiting a fake or compromised website. Visiting the website initiates the drive-by download. Malicious advertisements are another method that can allow drive-by downloads to infect your computer. Cybercriminals will purchase an advertisement spot on a legitimate webpage, but the ad they use will contain malicious code. So even if the page you’re visiting is reputable, the advertisements may not be. Clicking the ad will initiate the software download, and the cybercriminals will be one step closer to their goal — getting their hands on your data!
What Can I Do to Stay Safe?
Follow the tips below to keep yourself safe from drive-by downloads:
- Keep your software updated. The most recent software versions contain security updates that prevent drive-by downloads from occurring.
- Be cautious when clicking on advertisements or unexpected emails. Cybercriminals can use both methods to lure you into visiting a malicious web page.
- Only use web browser plugins or extensions that are approved by your organization. Unapproved software can have security flaws that leave your computer vulnerable to a drive-by download.
Source: KnowBe4 https://www.knowbe4.com/ KnowBe4 Security Tips - "Drive-By Downloads"
« Return to "Blog"